Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Cisco logo

CiscoCertified Network Professional Cybersecurity (CBRCOR)

Domain 1Objective 4

1.4 Infer the Industry for Various Compliance Standards Such as PCI, FISMA, FedRAMP, SOC, SOX, PCI, GDPR, Data Privacy, and ISO 27101 350-201 Practice Questions (Page 7)

Part of the Fundamentals domain, which accounts for 20% of the 350-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 1–2 from this objective — we provide 37 practice questions to prepare you well beyond it. (estimate)

37questions here
8free pages
8concepts
20%of the exam

Questions 31–35

  1. 31expert · hard

    A service organization provides payroll processing for several public companies. The organization also stores credit card numbers for a separate payment service. The external auditors of the public companies request a report on internal controls over financial reporting. Which report should the service organization provide to these auditors?

    Select an answer first
  2. 32expert · hard

    A multinational company is designing a data privacy program. It operates in the EU, processes payment card data, and is a U.S. federal contractor. The legal team wants to align with the most comprehensive set of requirements. Which combination of frameworks should the program incorporate?

    Select an answer first
  3. 33foundation · easy

    Which organization's scope is most likely to be subject to PCI DSS compliance requirements?

    Select an answer first
  4. 34expert · hard

    A multinational company is designing a new customer relationship management (CRM) system that will store personal data of customers in multiple countries. The company wants to implement a privacy framework that can adapt to various regulations and also align with its ISO/IEC 27101 ISMS. Which approach best supports this goal?

    Select an answer first
  5. 35application · medium

    A cloud service provider wants to sell its IaaS offering to multiple U.S. federal agencies. To avoid each agency performing its own security assessment, the provider seeks a standardized authorization that can be reused. Which program should the provider pursue?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “350-201” is a trademark of its owner, used for identification only.